StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,607
of 17,828 indexed, latest versions
Container images
5,326
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,607 of 17,828 indexed charts deploy, on 5,326 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,287
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,735
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,607 by stars
ChartLatestAffected imagesRadar Score
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.13.15
0.55.0
1.25.13

Open the chart page →

15,926
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.5
0.55.0
1.25.13

Open the chart page →

5,133
valheimgeek-cookbookVerified publisher4.4.21 of 1See more

valheim geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/lloesche/valheim-server:latestc885aa902faf
stdlib@go1.24.1
1.25.13

Open the chart page →

2,671
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.25.13

Open the chart page →

7,724
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.32 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

2 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.8512bb8a21483
stdlib@go1.19.10
1.25.13
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.25.13

Open the chart page →

14,566
geo-checkergeo-checkerVerified publisher5.0.01 of 1See more

geo-checker geo-checker 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ymuski/geo-checker:5.0.05ba7fd8c7bdc
stdlib@go1.25.3
1.25.13

Open the chart page →

1,461
gigapipegigapipeVerified publisher0.3.01 of 1See more

gigapipe gigapipe 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/metrico/gigapipe:v4.1.6caeb2652ce5e
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13

Open the chart page →

658
leantimegissilabs1.3.01 of 2See more

leantime gissilabs 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mariadb:10.6.218a16204dc96c
stdlib@go1.18.2
1.25.13

Open the chart page →

6,489
gitea-sonarqube-botgitea-sonarqube-botOfficialVerified publisher0.4.01 of 1See more

gitea-sonarqube-bot gitea-sonarqube-bot 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
justusbunsi/gitea-sonarqube-bot:v0.4.018dd43b470d9
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.55.0
1.25.13

Open the chart page →

1,146
temporalglasskubeVerified publisher0.45.2-gk.110 of 14See more

temporal glasskube 0.45.2-gk.1

10 of the 14 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.55.0
1.25.13
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
golang.org/x/net@v0.27.0
stdlib@go1.22.3
0.55.0
1.25.13
temporalio/server:1.25.08a5798191dea
golang.org/x/net@v0.28.0
stdlib@go1.22.3
0.55.0
1.25.13
temporalio/ui:2.30.25c2a3645d09c
golang.org/x/net@v0.28.0
stdlib@go1.22.1
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.55.0
1.25.13
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

16,418
go-hello-world-chartgo-hello-worldVerified publisher1.8.31 of 1See more

go-hello-world-chart go-hello-world 1.8.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/wasilak/go-hello-world:1.8.366d353e7693f
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.55.0
1.25.13

Open the chart page →

767
gomenhashaigomenhashaiOfficialVerified publisher1.3.41 of 1See more

gomenhashai gomenhashai 1.3.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/gomenhashai/gomenhashai:v1.3.36f031172a5ec
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.55.0
1.25.13

Open the chart page →

642
gorse-enterprisegorse-io0.4.23 of 5See more

gorse-enterprise gorse-io 0.4.2

3 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.55.0
1.25.13
zhenghaoz/gorse-server:0.4.1239c565685b01
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.55.0
1.25.13
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.55.0
1.25.13

Open the chart page →

4,438
gotosocialgotosocialVerified publisher0.2.321 of 1See more

gotosocial gotosocial 0.2.32

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
superseriousbusiness/gotosocial:0.22.10078ca451dda
stdlib@go1.25.12
1.25.13

Open the chart page →

303
meta-monitoringgrafana1.3.02 of 2See more

meta-monitoring grafana 1.3.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/alloy:v1.4.306bdcbb51fc2
golang.org/x/net@v0.29.0
stdlib@go1.22.7
0.55.0
1.25.13
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.25.13

Open the chart page →

3,604
phlaregrafana0.5.41 of 1See more

phlare grafana 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/phlare:0.5.1330f990cdad9
golang.org/x/net@v0.5.0
stdlib@go1.19.6
0.55.0
1.25.13

Open the chart page →

2,091
greenkubegreenkubeVerified publisher0.3.01 of 3See more

greenkube greenkube 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:18-alpine6c538e7206ea
stdlib@go1.24.6
1.25.13

Open the chart page →

1,455
armada-operatorgresearch0.7.02 of 2See more

armada-operator gresearch 0.7.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gresearch/armada-operator:latest6c43743e2b2d
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.55.0
1.25.13
kubebuilder/kube-rbac-proxy:v0.16.03c4f708c6204
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.55.0
1.25.13

Open the chart page →

1,583
carettagroundcover0.0.163 of 3See more

caretta groundcover 0.0.16

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.18
0.55.0
1.25.13
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/net@v0.1.0
stdlib@go1.19.3
0.55.0
1.25.13
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.55.0
1.25.13

Open the chart page →

6,821
ghostgroundhog2k0.212.131 of 1See more

ghost groundhog2k 0.212.13

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/ghost:6.64.0a31d03f1f629
stdlib@go1.26.4
1.25.13

Open the chart page →

2,014
growthbookgrowthbook5.0.11 of 2See more

growthbook growthbook 5.0.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnami/mongodb:lateste46cffb66274
stdlib@go1.26.5
1.25.13

Open the chart page →

752
IMgrycapOfficialVerified publisher1.8.01 of 3See more

IM grycap 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.485b9bf2e29cf
stdlib@go1.24.6
1.25.13

Open the chart page →

4,227
oscargrycapOfficialVerified publisher4.1.31 of 2See more

oscar grycap 4.1.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/grycap/oscar:latest0c58ff972451
golang.org/x/net@v0.51.0
stdlib@go1.25.11
0.55.0
1.25.13

Open the chart page →

432
castopodh2mVerified publisher1.12.101 of 3See more

castopod h2m 1.12.10

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
castopod/castopod:1.12.101fd37280cbb2
stdlib@go1.21.13
1.25.13

Open the chart page →

10,085
haproxy-unified-gatewayhaproxytechVerified publisher1.2.01 of 1See more

haproxy-unified-gateway haproxytech 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
haproxytech/haproxy-unified-gateway:1.0.7b9bffe2d0fd1
stdlib@go1.26.5
1.25.13

Open the chart page →

675
boundary-controllerhashicorpVerified publisher0.1.11 of 1See more

boundary-controller hashicorp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hashicorp/boundary-enterprise:1.0.1-ent38d2f9bdee0d
stdlib@go1.26.4
1.25.13

Open the chart page →

304
boundary-workerhashicorpVerified publisher0.1.11 of 1See more

boundary-worker hashicorp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hashicorp/boundary-enterprise:1.0.1-ent38d2f9bdee0d
stdlib@go1.26.4
1.25.13

Open the chart page →

304
terraform-cloud-operatorhashicorpVerified publisher2.5.02 of 2See more

terraform-cloud-operator hashicorp 2.5.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hashicorp/terraform-cloud-operator:2.5.0c2f78a575a8a
golang.org/x/net@v0.24.0
stdlib@go1.22.4
0.55.0
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.18.0754ab2a723c8
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13

Open the chart page →

1,478
hawkhawk1.1.53 of 4See more

hawk hawk 1.1.5

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.17.9
0.55.0
1.25.13
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.25.13
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
golang.org/x/net@v0.19.0
stdlib@go1.20.11
0.55.0
1.25.13

Open the chart page →

13,679
clickstackhdx-oss-v21.1.11 of 5See more

clickstack hdx-oss-v2 1.1.1

1 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:5.0.32-focal3b6c281e1c08
golang.org/x/net@v0.47.0
stdlib@go1.24.0
0.55.0
1.25.13

Open the chart page →

4,775
headscale-uiheadscale-uiVerified publisher0.2.91 of 1See more

headscale-ui headscale-ui 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/gurucomputing/headscale-ui:2026.03.17015f5ba04bcb
golang.org/x/net@v0.42.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

1,502
guacamolehelmforgeVerified publisher1.5.22 of 5See more

guacamole helmforge 1.5.2

2 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie86c951e05bf5
stdlib@go1.24.6
1.25.13
library/postgres:17.5-bookwormfbcea1bd13b6
stdlib@go1.18.2
1.25.13

Open the chart page →

8,568
mariadbhelmforgeVerified publisher2.1.11 of 1See more

mariadb helmforge 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mariadb:12.3.3805c8e104bd5
stdlib@go1.24.6
1.25.13

Open the chart page →

1,643
matomohelmforgeVerified publisher2.3.01 of 3See more

matomo helmforge 2.3.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:9.7.2b2cf29815e62
stdlib@go1.24.6
1.25.13

Open the chart page →

2,747
uptime-kumahelmforgeVerified publisher1.5.131 of 1See more

uptime-kuma helmforge 1.5.13

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
stdlib@go1.20.5
1.25.13

Open the chart page →

30,728
velerohelmforgeVerified publisher1.4.102 of 2See more

velero helmforge 1.4.10

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
velero/velero:v1.18.237396519f399
stdlib@go1.25.11
1.25.13
velero/velero-plugin-for-aws:v1.14.07e82f717f44e
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

1,462
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.55.0
1.25.13

Open the chart page →

4,251
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.12
0.55.0
1.25.13

Open the chart page →

6,990
spirehelm-spireVerified publisher0.30.24 of 10See more

spire helm-spire 0.30.2

4 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.55.0
1.25.13
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
golang.org/x/net@v0.42.0
stdlib@go1.25.3
0.55.0
1.25.13
ghcr.io/spiffe/spire-controller-manager:0.7.0d7b9e710f542
stdlib@go1.26.5
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

1,688
helmuphelmupVerified publisher0.1.01 of 3See more

helmup helmup 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
golang.org/x/net@v0.15.0
stdlib@go1.20.4
0.55.0
1.25.13

Open the chart page →

16,517
hivemq-platform-operatorhivemqOfficialVerified publisher0.2.261 of 1See more

hivemq-platform-operator hivemq 0.2.26

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hivemq/hivemq-platform-operator:2.2.2a919f990141b
stdlib@go1.26.5
1.25.13

Open the chart page →

950
hiverhiverVerified publisher0.1.459 of 10See more

hiver hiver 0.1.45

9 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hiversh/antigravity:0.1.45-microvm0e36d98402bc
stdlib@go1.26.5
1.25.13
hiversh/browser:0.1.45-microvmb5048c6342ce
stdlib@go1.26.5
1.25.13
hiversh/claude:0.1.45-microvm2fbf9f264498
stdlib@go1.26.5
1.25.13
hiversh/codex:0.1.45-microvm4f43130f51e5
stdlib@go1.26.5
1.25.13
hiversh/controller:0.1.45b0b85f8942c7
stdlib@go1.19.8
1.25.13
hiversh/copilot:0.1.45-microvm50c07b84f298
stdlib@go1.26.5
1.25.13
hiversh/node:0.1.45-alpine-microvm836a37641941
stdlib@go1.26.5
1.25.13
hiversh/openclaw:0.1.45-microvm958b7ebb4eb4
stdlib@go1.19.8
1.25.13
hiversh/python:0.1.45-3.13-alpine-microvm63a5ae179a9f
stdlib@go1.19.8
1.25.13

Open the chart page →

21,549
cratedb-adapter-v2hmdmph0.2.11 of 1See more

cratedb-adapter-v2 hmdmph 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
stdlib@go1.16.3
0.55.0
1.25.13

Open the chart page →

2,921
holoinsightholoinsight0.2.52 of 6See more

holoinsight holoinsight 0.2.5

2 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
holoinsight/otelcontribcol:latest42ba8dc3113c
golang.org/x/net@v0.8.0
stdlib@go1.19
0.55.0
1.25.13
library/mysql:885b9bf2e29cf
stdlib@go1.24.6
1.25.13

Open the chart page →

27,901
holoinsight-agentholoinsight0.2.51 of 2See more

holoinsight-agent holoinsight 0.2.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
holoinsight/agent:latest5c3994e742f8
golang.org/x/net@v0.5.0
stdlib@go1.22.1
0.55.0
1.25.13

Open the chart page →

1,804
openprojecthomeenterpriseinc0.5.01 of 1See more

openproject homeenterpriseinc 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
openproject/community:12.0.2734743d11094
stdlib@go1.17
1.25.13

Open the chart page →

6,818
honeycombhoneycomb1.9.31 of 1See more

honeycomb honeycomb 1.9.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
honeycombio/honeycomb-kubernetes-agent:2.7.448c38d0870f2
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

437
hpe-greenlake-file-csi-driverhpe-storageVerified publisher2.6.45 of 7See more

hpe-greenlake-file-csi-driver hpe-storage 2.6.4

5 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v6.1.0e5900dc98b0d
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

6,314
htnn-controllerhtnnVerified publisher0.5.01 of 1See more

htnn-controller htnn 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
golang.org/x/net@v0.24.0
stdlib@go1.21.12
0.55.0
1.25.13

Open the chart page →

4,373
demoryhuseyinbabalOfficialVerified publisher0.7.01 of 1See more

demory huseyinbabal 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
golang.org/x/net@v0.0.0-20210907225631-ff17edfbf26d
stdlib@go1.17.2
0.55.0
1.25.13

Open the chart page →

1,580

Container images carrying it

5,326 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.55.0
1.25.13
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.2050a34002d5b
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.33d671cf20a35
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.55.0
1.25.13
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.044d1d0e9f19c
golang.org/x/net@v0.21.0
stdlib@go1.21.6
0.55.0
1.25.13
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.55.0
1.25.13
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.0aaafd456bda1
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.1e63459ec5965
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.55.0
1.25.13
1
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.55.0
1.25.13
1
registry.k8s.io/kro/kro:v0.9.4eaf9fbaddd9d
stdlib@go1.26.3
1.25.13
1
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.55.0
1.25.13
1
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.55.0
1.25.13
1
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.55.0
1.25.13
1
registry.k8s.io/kubectl:1.33.4261a9ed843eb
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.55.0
1.25.13
1
registry.k8s.io/kubectl:v1.32.73c5268158974
golang.org/x/net@v0.30.0
stdlib@go1.23.10
0.55.0
1.25.13
1
registry.k8s.io/kubectl:v1.35.64d8c68e8c2bf
golang.org/x/net@v0.47.0
stdlib@go1.25.11
0.55.0
1.25.13
1
registry.k8s.io/kubectl:v1.34.159bafa07ff3a
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.55.0
1.25.13
1
registry.k8s.io/kubectl:v1.32.08ccae74fc039
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.55.0
1.25.13
1
registry.k8s.io/kubectl:v1.36.2b0d792e0d8df
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.55.0
1.25.13
1
registry.k8s.io/kubectl:v1.36.1d08f476d04d0
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.55.0
1.25.13
1
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
golang.org/x/net@v0.26.0
stdlib@go1.23.10
0.55.0
1.25.13
1
registry.k8s.io/kube-scheduler:v1.26.110684e23172d9
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.55.0
1.25.13
1
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
1
registry.k8s.io/kube-scheduler:v1.23.143e149d206076
stdlib@go1.17.13
1.25.13
1
registry.k8s.io/kube-scheduler:v1.28.1146cf7475c8da
golang.org/x/net@v0.23.0
stdlib@go1.21.11
0.55.0
1.25.13
1
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.55.0
1.25.13
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.55.0
1.25.13
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.2ec5732e28f15
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.55.0
1.25.13
1
registry.k8s.io/kwok/kwok:v0.8.06d25aa8fbdfe
golang.org/x/net@v0.51.0
stdlib@go1.26.0
0.55.0
1.25.13
1
registry.k8s.io/metrics-server/metrics-server:v0.7.01c0419326500
golang.org/x/net@v0.20.0
stdlib@go1.21.6
0.55.0
1.25.13
1
registry.k8s.io/metrics-server/metrics-server:v0.7.1db3800085a09
golang.org/x/net@v0.20.0
stdlib@go1.21.8
0.55.0
1.25.13
1
registry.k8s.io/nfd/node-feature-discovery:v0.16.619ebca8b3804
golang.org/x/net@v0.25.0
stdlib@go1.22.8
0.55.0
1.25.13
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
golang.org/x/net@v0.27.0
stdlib@go1.23.2
0.55.0
1.25.13
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13
1
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.55.0
1.25.13
1
registry.k8s.io/provider-os/cinder-csi-plugin:v1.36.078adaeb154c7
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13
1
registry.k8s.io/provider-os/openstack-cloud-controller-manager:v1.36.0e354e40db2d0
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13
1
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
golang.org/x/net@v0.4.0
stdlib@go1.19
0.55.0
1.25.13
1
registry.k8s.io/sig-storage/csi-attacher:v4.5.19dcd469f02bb
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.55.0
1.25.13
1
registry.k8s.io/sig-storage/csi-attacher:v4.10.0be59d0556508
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.55.0
1.25.13
1
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.55.0
1.25.13
1
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
golang.org/x/net@v0.0.0-20220802222814-0bcc04d9c69b
stdlib@go1.18
0.55.0
1.25.13
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
golang.org/x/net@v0.17.0
stdlib@go1.20.5
0.55.0
1.25.13
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
golang.org/x/net@v0.4.0
stdlib@go1.19
0.55.0
1.25.13
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.55.0
1.25.13
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15
0.55.0
1.25.13
1
registry.k8s.io/sig-storage/csi-provisioner:v5.0.27b9cdb5830d0
golang.org/x/net@v0.25.0
stdlib@go1.22.5
0.55.0
1.25.13
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
golang.org/x/net@v0.4.0
stdlib@go1.19
0.55.0
1.25.13
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.